Password Reset Vulnerability in SysReptor Pentest Reporting Platform
CVE-2026-81179

8.1HIGH

Key Information:

Vendor

Syslifters

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-81179?

The SysReptor Pentest Reporting Platform has a vulnerability where prior to version 2026.58, installations that allow password resets via email with a misconfigured ALLOWED_HOSTS setting can be exploited. An attacker can manipulate the Host header during the password reset process to redirect the victim to an attacker-controlled domain. This scenario enables an unauthenticated attacker to obtain a password reset link containing a sensitive token, allowing them to reset the victim's password and gain unauthorized access to the account. Proper email gateway configuration and potential misconfigurations in reverse proxy setups can influence the effectiveness of this attack. The issue has been resolved in version 2026.58, highlighting the importance of strict validation of Host headers.

Affected Version(s)

sysreptor < 2026.58

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.